Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Multiple F5 Networks Products - ConfigSync IP Rsync full file system access vulnerability CVE-2014-2927 - Active Check

Information

Severity

Severity

Critical

Family

Family

Gain a shell remotely

CVSSv2 Base

CVSSv2 Base

9.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

9 years ago

Modified

Modified

2 years ago

Summary

Multiple F5 Networks Products are prone to a remote code-execution (RCE) vulnerability.

Insight

Insight

An open Rsync configuration for the ConfigSync IP address allows for remote read/write file system access.

Affected Software

Affected Software

F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11. Enterprise Manager 3.x before 3.1.1 HF2.

Detection Method

Detection Method

Tries to read the /VERSION file via a rsync request.

Solution

Solution

Disable the rsync daemon or update to a fixed version listed at the referenced vendor advisory.

Common Vulnerabilities and Exposures (CVE)